← Back to CVE List

CVE-2018-20149

Published: 2018-12-14T20:29Z
Last Modified: 2024-11-21T04:00Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS, as demonstrated by a .jpg file without JPEG data. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt